encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-2632 encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacker might cause a denial of service condition by sending an HTTP request with an extremely long "id" parameter.
Github GHSA Github GHSA GHSA-3px7-jm2p-6h2c encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 18 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-06-18T15:43:39.641Z

Reserved: 2024-01-04T18:44:55.210Z

Link: CVE-2024-0241

cve-icon Vulnrichment

Updated: 2024-08-01T17:41:16.398Z

cve-icon NVD

Status : Modified

Published: 2024-01-04T21:15:09.267

Modified: 2025-06-18T16:15:26.000

Link: CVE-2024-0241

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.